Snarky Spider is a financially motivated eCrime threat cluster associated with The Com and closely aligned with the broader Scattered Spider ecosystem. It is also tracked as O-UNC-025 and UNC6661. The group has been active since at least October 2025 and is known for rapid data-theft and extortion operations that rely heavily on social engineering and identity compromise rather than malware-heavy intrusion chains. Snarky Spider specializes in voice-phishing-led intrusions against enterprise identity platforms and SaaS environments. Operators impersonate IT or help-desk personnel, direct victims to adversary-in-the-middle single sign-on pages, and capture credentials, multifactor authentication material, and session data. After compromising an identity provider account, the group abuses trust relationships between the identity platform and connected cloud services to access multiple SaaS applications with minimal endpoint footprint. Reported victim environments include Microsoft 365, Google Workspace, SharePoint, HubSpot, and Salesforce. The group is notable for speed. In documented incidents, Snarky Spider moved from account takeover to data theft in under five minutes, and in other cases began high-volume exfiltration within an hour of initial compromise. Post-compromise activity includes registering attacker-controlled MFA devices for persistence, removing existing MFA devices, deleting security notifications, and creating inbox rules to suppress alerts related to unauthorized access or MFA changes. The actor also scrapes internal directories and conducts additional social engineering to identify and target privileged accounts. Snarky Spider operates primarily inside trusted SaaS environments and relies on living-off-the-land tradecraft, valid accounts, and residential proxy or VPN services to reduce detection opportunities and blend with normal user activity. Its campaigns focus on stealing sensitive business data for extortion, and reporting also links the group to aggressive pressure tactics including victim harassment and, in some cases, DDoS against non-paying victims. Targeting has been concentrated on U.S.-based organizations across sectors including academia, aviation, retail, hospitality, automotive, financial services, legal, and technology.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses voice phishing to compromise SSO accounts, take over accounts, and steal data from SaaS applications with very rapid execution.
Uses vishing for initial access, compromises single sign-on accounts, accesses cloud productivity environments, and rapidly moves from account takeover to data theft.
eCrime activity involving rapid progression from account takeover to data theft.
Uses vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.